• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

403 4.7.0 TLS handshake failed

ErwanG

Regular Pleskian
Hello,

Some emails are not delivery to Qmail server (Plesk 12). Error message:

Deferred: 403 4.7.0 TLS handshake failed.


What's the problem? I have found nothing about that...

Thank you.

Erwan
 
Make sure that you have file /var/qmail/control/tlsserverciphers with following content:

ALL:!ADH:!LOW:!SSLv2:!SSLv3:!EXP:+HIGH:+MEDIUM
 
There is no problem with most of the users but for some:
- error message with: 403 4.7.0 TLS handshake failed
- no error message but the noting in the recepient account...

In the log there isn't no trace.

I don't understand. It seems to be a problem since Poodle & Beast update for this server.
 
Another thing (related?) : with Horde, we can not send message.

Error: Could not open secure TLS connection to the server
 
Igor,

From another server to the server:

#openssl s_client -starttls smtp -connect pop3.xxx.com:25

I have:
....
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-GCM-SHA384
...
Is Cipher correct?
 
On my test 12.0 Plesk server with default installation I see:

New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
 
Igor,

If i change mail server (Qmail) to Postfix, is the ssl config is reset or no?
Or how i can reset ssl config?
 
We have had the problem with 3 servers. We have tested the migration on one of them yesterday night.
It seems that the problem disapear.
 
Back
Top